CRITICAL 9.9 CVE-2026-77240 Published 18 Sept 2026

WACRM Self-Promotion & Tenant Access Vulnerability

Worried this affects your website?

WACRM, a self-hostable CRM template for WhatsApp, is affected.

In versions 0.7.0 and earlier, authenticated users can modify their own account role and ID, allowing self-promotion or access to other tenants' resources.

Additionally, certain knowledge-base chunks can be read by authenticated non-members of another tenant.

Reference: CVE-2026-77240 on NVD

← Back to Security News